]> Git — Sourcephile - sourcephile-nix.git/blob - servers/losurdo/Makefile
losurdo: booting on that specific NVMe M.2 is not (yet?) supported
[sourcephile-nix.git] / servers / losurdo / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 #disk := /dev/disk/by-id/usb-Generic-_Multi-Card_20071114173400000-0:0
3 #disk := /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_Plus_250GB_S4EUNJ0N211426T
4 server := losurdo
5 disk := $(shell sourcephile-nix-get nodes.$(server).config.boot.loader.grub.devices.0)
6 partlabel := $(server)_sd
7 rpool := $(partlabel)
8 cipher := aes-128-gcm
9 autotrim := on
10 reservation := 1G
11
12 wipeout:
13 sudo modprobe zfs
14 sudo zpool labelclear -f $(disk)-part4 || true
15 sudo $$(which sgdisk) --zap-all $(disk)
16
17 partition: wipeout
18 sudo $$(which sgdisk) -a1 -n0:34:2047 -t0:EF02 -c0:"$(partlabel)_bios" $(disk)
19 sudo $$(which sgdisk) -n0:1M:+100M -t0:EF00 -c0:"$(partlabel)_efi" $(disk)
20 sudo $$(which sgdisk) -n0:0:+256M -t0:8300 -c0:"$(partlabel)_boot" $(disk)
21 #sudo $$(which sgdisk) -n0:0:+8G -t0:8200 -c0:"$(partlabel)_swap" $(disk)
22 sudo $$(which sgdisk) -n0:0:0 -t0:BF01 -c0:"$(partlabel)_rpool" $(disk)
23 sudo $$(which sgdisk) --randomize-guids $(disk)
24 sudo $$(which sgdisk) --backup=$(partlabel).sgdisk $(disk)
25
26 format: umount format-efi format-boot format-rpool
27 format-efi:
28 sudo blkid $(disk)-part2 -t TYPE=vfat || \
29 sudo mkfs.vfat -F 16 -s 1 -n EFI $(disk)-part2
30 format-boot:
31 sudo mkdir -p /mnt/$(server)
32 sudo blkid -t TYPE=ext2 $(disk)-part3; test $$? != 2 || \
33 sudo mkfs.ext2 $(disk)-part3
34 format-rpool:
35 sudo zpool list $(rpool) 2>/dev/null || \
36 sudo zpool create -o ashift=12 \
37 $(if $(cipher),-O encryption=$(cipher) \
38 -O keyformat=passphrase \
39 -O keylocation=prompt) \
40 -O normalization=formD \
41 -R /mnt/$(server) $(rpool) $(disk)-part4
42 sudo zpool set \
43 autotrim=$(autotrim) \
44 $(rpool)
45 sudo zfs set \
46 acltype=posixacl \
47 atime=off \
48 canmount=off \
49 compression=lz4 \
50 dnodesize=auto \
51 relatime=on \
52 xattr=sa \
53 mountpoint=/ \
54 $(rpool)
55 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
56 sudo zfs list $(rpool)/reserved 2>/dev/null || \
57 sudo zfs create -o canmount=off -o mountpoint=none $(rpool)/reserved
58 sudo zfs set refreservation=$(reservation) $(rpool)/reserved
59 # /
60 # mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
61 sudo zfs list $(rpool)/root 2>/dev/null || \
62 sudo zfs create \
63 -o canmount=on \
64 -o mountpoint=legacy \
65 $(rpool)/root
66 # /boot
67 #sudo zfs list bpool/boot 2>/dev/null || \
68 #sudo zfs create \
69 # -o canmount=on \
70 # -o mountpoint=legacy \
71 # bpool/boot
72 # /*
73 for p in \
74 home \
75 nix \
76 var \
77 var/cache \
78 var/log \
79 var/tmp \
80 ; do \
81 sudo zfs list $(rpool)/"$$p" 2>/dev/null || \
82 sudo zfs create \
83 -o canmount=on \
84 -o mountpoint=legacy \
85 $(rpool)/"$$p" ; \
86 done
87 sudo zfs set \
88 com.sun:auto-snapshot=false \
89 $(rpool)/nix
90 sudo zfs set \
91 com.sun:auto-snapshot=false \
92 $(rpool)/var/cache
93 sudo zfs set \
94 com.sun:auto-snapshot=false \
95 sync=disabled \
96 $(rpool)/var/tmp
97
98 mount: mount-rpool mount-boot mount-efi
99 mount-rpool:
100 # scan needed zpools
101 sudo zpool list $(rpool) || \
102 sudo zpool import -f $(rpool)
103 # load encryption key
104 sudo zfs get -H encryption $(rpool) | \
105 grep -q '^$(rpool)\s*encryption\s*off' || \
106 sudo zfs get -H keystatus $(rpool) | \
107 grep -q '^$(rpool)\s*keystatus\s*available' || \
108 sudo zfs load-key $(rpool)
109 # /
110 sudo mkdir -p /mnt/$(server)
111 sudo mountpoint /mnt/$(server) || \
112 sudo mount -v -t zfs $(rpool)/root /mnt/$(server)
113 # /*
114 for p in \
115 home \
116 nix \
117 var \
118 var/cache \
119 var/log \
120 var/tmp \
121 ; do \
122 sudo mkdir -p /mnt/$(server)/"$$p"; \
123 sudo mountpoint /mnt/$(server)/"$$p" || \
124 sudo mount -v -t zfs $(rpool)/"$$p" /mnt/$(server)/"$$p" ; \
125 done
126 sudo chmod 1777 /mnt/$(server)/var/tmp
127 mount-boot:
128 sudo mkdir -p /mnt/$(server)/boot
129 sudo mountpoint /mnt/$(server)/boot || \
130 sudo mount -v $(disk)-part3 /mnt/$(server)/boot
131 #sudo mount -v -t zfs bpool/boot /mnt/$(server)/boot
132 mount-efi: | mount-boot
133 sudo mkdir -p /mnt/$(server)/boot/efi
134 sudo mountpoint /mnt/$(server)/boot/efi || \
135 sudo mount -v $(disk)-part2 /mnt/$(server)/boot/efi
136
137 bootstrap: mount
138 # Workaround https://dev.gnupg.org/T3908
139 chmod o+rw $$GPG_TTY $$XAUTHORITY
140
141 sudo --preserve-env \
142 NIXOS_CONFIG="$$PWD/configuration.nix" \
143 $$(which nixos-install) \
144 --root /mnt/$(server) \
145 --no-root-passwd \
146 --no-channel-copy \
147 --show-trace
148
149 # End workaround https://dev.gnupg.org/T3908
150 chmod o-rw $$GPG_TTY $$XAUTHORITY
151
152 sudo sourcephile-shred-tmp
153
154 umount:
155 for p in \
156 boot/efi \
157 boot \
158 home \
159 nix \
160 var/cache \
161 var/log \
162 var/tmp \
163 var \
164 "" \
165 ; do \
166 ! sudo mountpoint /mnt/$(server)/"$$p" || \
167 sudo umount -v /mnt/$(server)/"$$p" ; \
168 done
169 ! sudo zpool list $(rpool) 2>/dev/null || \
170 zfs get -H encryption $(rpool) | \
171 grep -q '^$(rpool)\s*encryption\s*off' || \
172 zfs get -H keystatus $(rpool) | \
173 grep -q '^$(rpool)\s*keystatus\s*unavailable' || \
174 sudo zfs unload-key $(rpool)
175 #! sudo zpool list bpool 2>/dev/null || \
176 #sudo zpool export bpool
177 ! sudo zpool list $(rpool) 2>/dev/null || \
178 sudo zpool export $(rpool)
179
180 unlock:
181 pass servers/$(server)/zfs/$(rpool) | \
182 NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
183 nixops ssh $(server) -p 2222 'zfs load-key $(rpool) && pkill zfs'